GHSA-m9gg-hp2v-232j

Suggest an improvement
Source
https://github.com/advisories/GHSA-m9gg-hp2v-232j
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-m9gg-hp2v-232j/GHSA-m9gg-hp2v-232j.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-m9gg-hp2v-232j
Aliases
Published
2026-09-30T15:35:53Z
Modified
2026-09-30T15:45:30Z
Severity
  • 7.4 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
@grpc/grpc-js: In certain configurations, getAuthContext can return unauthorized certificates as though they were authorized
Details

Impact

When server credentials are created with the requireClientCertificate option set to false, getAuthContext does not distinguish between authorized and unauthorized certificates in its return value. This can create improper authentication vulnerabilities for @grpc/grpc-js users who use the result of getAuthContext for authentication.

In particular, @grpc/grpc-js-xds can both set the requireClientCertificate option to false and use the return value of getAuthContext for RBAC authentication in some configurations.

Patches

This vulenrability is fixed in 1.13.6 and 1.14.5.

Workarounds

@grpc/grpc-js users using getAuthContext this way can avoid this problem by setting requireClientCertificate to true. @grpc/grpc-js-xds users using RBAC can avoid this by setting the require_client_certificate field to true in the DownstreamTlsContext in the xDS configuration.

Database specific
{
    "cwe_ids":  [
        "CWE-295"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-30T15:35:53Z",
    "nvd_published_at":  "2026-09-28T21:17:13Z",
    "severity":  "HIGH"
}
References

Affected packages

npm / @grpc/grpc-js

Package

Name
@grpc/grpc-js
View open source insights on deps.dev
Purl
pkg:npm/%40grpc/grpc-js

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.13.6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-m9gg-hp2v-232j/GHSA-m9gg-hp2v-232j.json"

npm / @grpc/grpc-js

Package

Name
@grpc/grpc-js
View open source insights on deps.dev
Purl
pkg:npm/%40grpc/grpc-js

Affected ranges

Type
SEMVER
Events
Introduced
1.14.0
Fixed
1.14.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-m9gg-hp2v-232j/GHSA-m9gg-hp2v-232j.json"